Nine processors cover more than face swapping
FaceFusion starts with the familiar job of putting a source face into a target image or video. Its processor list goes further: age changes, expression restoration, face debugging, face enhancement, face editing, frame colorization, frame enhancement, and lip sync can join the default face swapper. You can select more than one processor for the same job, then tune detector, landmark, mask, output, and memory settings in the interface or configuration file.
The browser UI is only one entry point. headless-run handles scripted work, batch-run applies a pattern, and the job commands create, edit, submit, retry, and delete queued jobs. A webcam layout can render inside the UI or send a UDP or V4L2 stream to OBS. Those modes make FaceFusion a media application rather than a single notebook, especially when you need to repeat the same settings across a folder.
The documented install assumes Conda and accelerator knowledge
The project warns that installation requires technical skill. Its supported path initializes Conda, creates a Python 3.12 environment with pip 25.0, clones the repository, and runs the installer for the chosen execution backend. CPU is available, while documented providers include CoreML, CUDA, DirectML, MIGraphX, ROCm, TensorRT, and OpenVINO. A configuration can also name device IDs and set execution threads from 1 through 32.
That choice is useful, but each backend carries its own driver and runtime expectations. The repository's requirements pin Gradio, NumPy, ONNX, ONNX Runtime, OpenCV, SciPy, and other packages. Model files arrive separately as processors need them. The official Docker page points to facefusion/facefusion-docker, with different Compose files and ports for CPU, CUDA, TensorRT, and ROCm. Our measured source checkout had no Dockerfile, so container users are maintaining two repositories.
What happened when we ran it
We tested commit 7247081 in a fresh Debian sandbox with 3 CPUs, 8 GB of RAM, Python 3.12, no secrets, and no elevated privileges. Installation succeeded in 29 seconds, bringing in 87 packages and consuming 780 MB. The build completed in another 6 seconds. The checkout was 2.1 MB, with 247 files and about 23,048 lines of source.
The test step failed after 46 seconds. Pytest reported 97 passed, 13 failed, 4 skipped, and 128 collection/setup errors of 238. Several failures in face tracking and frame storage ended with TypeError because a path value was None. Five inference-pool cases failed assertions, and the static-provider test ended with ModuleNotFoundError: No module named 'test'. The supplied tail does not reveal what produced those states.
Pip-audit also found 58 known vulnerabilities. The result did not include severity or exploitability, so we will not turn that count into an incident claim. It is still a large review queue for software that accepts private faces, videos, and audio. Record each affected package, determine whether the vulnerable code is reachable, upgrade where supported, and rerun the same media path before exposing a service.
Model licenses can rule out commercial output
The application is distributed under OpenRAIL-AS, and GitHub does not map the repository to a standard SPDX license identifier. The project's license page says supplied assets retain their own terms. Its table includes MIT and Apache models, but it also labels several non-commercial, ResearchRAIL, S-Lab 1.0, or unknown. Choosing a model in the UI does not make those differences disappear.
A commercial team needs a bill of materials for the exact detector, recognizer, swapper, enhancer, and lip-sync models in use. Keep the model name and revision with every preset, then have someone qualified review the terms before publishing output. This is especially important when a workflow combines processors, since one restricted model can change whether the whole result is usable for a client. Open source application code does not grant rights to a person's likeness either.
The project also acknowledges misuse risk and says it blocks nudity, graphic material, and sensitive content. It rejects pornographic and unauthorized use. Those safeguards state the maintainers' position; they do not replace consent, local law, or editorial disclosure. A responsible pipeline should log the source, permission, operator, model selection, and output destination before processing starts.
September 30 brought both v3.9.1 and a fresh push
FaceFusion was pushed on September 30, 2026, and release 3.9.1 appeared the same day. That patch updated ONNX Runtime, narrowed an arena workaround to affected versions, and fixed content-analyser performance with CoreML. GitHub showed 30,093 stars and zero open issues or pull requests. The recent merged history includes session separation, job cleanup, output exposure through the API, and video frame-rate fixes.
The pace is healthy, but our measured commit is not ready for blind automation. A 6-second build does not offset 13 failing tests, 128 setup or collection errors, and 58 audit findings. FaceFusion remains worth a controlled trial because the UI and job system cover real production chores. The acceptance gate should be your own consented footage on the intended accelerator, followed by a clean dependency decision and a written model-license record.

